<?xml version="1.0" encoding="UTF-8" ?>

<rss version="2.0"
  xmlns:ent="http://www.purl.org/NET/ENT/1.0/"
  xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
  <title>Musings on Information Security</title>
  <link>http://ravichar.blogharbor.com/blog</link>
  <description></description>
  <language>en-us</language>
  <lastBuildDate>Thu, 28 May 2009 14:07:28 -0700</lastBuildDate>
  <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
  <generator>Blogware</generator>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>More money for information security in this recession economy... Oh yeah!</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2009/5/28/4203287.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2009/5/28/4203287.html</guid>
    <pubDate>Thu, 28 May 2009 06:50:49 -0700</pubDate>
    <description>&lt;P&gt;Information security investments are hard to justify in good times and harder to justify in bad times. If you invest wisely in information security&amp;nbsp;and prevent bad stuff from happening there won&#39;t be sensational security incidents and thus no visibility -&amp;nbsp;kind of catch-22 is it not?&lt;/P&gt;
&lt;P&gt;There is another way to get security budget than asking for security budget right off&amp;nbsp; the bat. For that we need to understand that&amp;nbsp;a&amp;nbsp;customer who is educated about&amp;nbsp;information security&amp;nbsp;is always a happy customer. Senior management is a customer of information security service that you offer. You&amp;nbsp;have to&amp;nbsp;work up to get their attention.&lt;/P&gt;
&lt;P&gt;- Publish information security articles&amp;nbsp;company&#39;s newsletters.&lt;/P&gt;
&lt;P&gt;- Publish news item about information security on company&#39;s Intranet. &lt;/P&gt;
&lt;P&gt;- Set up information security booth at company&#39;s events, keep raffle prizes else no one will visit your booth I promise!&lt;/P&gt;
&lt;P&gt;- Launch companywide information security awareness training and also give security awareness presentation to executives.&lt;/P&gt;
&lt;P&gt;- Distribute security awareness&amp;nbsp;flyers.&lt;/P&gt;
&lt;P&gt;- Give awards to a developer following good security practice.&lt;/P&gt;
&lt;P&gt;- Make security fun, announce a crypto&amp;nbsp;challenge, and&amp;nbsp;&amp;nbsp;kepp attractive prizes (iPod, IronKey)&amp;nbsp;for the winners.&lt;/P&gt;
&lt;P&gt;All the above can create a background for information security, this leads to conversations which creates perception of information security. By the time you go to the upper management to ask for budget half the battle is won. The other half is to communicate to senior management in&amp;nbsp;a language of risk (which they understand).&amp;nbsp;Don&#39;t ask for&amp;nbsp;budget right away, dialogue with&amp;nbsp;senior management in order to&amp;nbsp;understand&amp;nbsp;an acceptable business risk profile, then&amp;nbsp;propse a&amp;nbsp;security solution which can provide that risk profile. Lastly, ask for money to provide the security solution. Since they accepted the risk profile, I bet you are likely to get the money!&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Pragmatic Web Application Security</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2009/3/20/4128292.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2009/3/20/4128292.html</guid>
    <pubDate>Fri, 20 Mar 2009 07:15:03 -0700</pubDate>
    <description>&lt;P&gt;I have condensed my earlier series of articles on Pragmatic Web Application Security into a single document. &lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://ravichar.blogharbor.com/Pragmatic%20Web%20Application%20Security.pdf&quot;&gt;http://ravichar.blogharbor.com/Pragmatic%20Web%20Application%20Security.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Feedback?, you can reach me at: RaviChar AT GMAIL DOT COM&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Pragmatic Web Application Security - Part 9 - Summary &amp; Conclusion</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2009/3/20/4128274.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2009/3/20/4128274.html</guid>
    <pubDate>Fri, 20 Mar 2009 07:06:12 -0700</pubDate>
    <description>&lt;TABLE width=631&gt;
&lt;TBODY&gt;
&lt;TR vAlign=top&gt;
&lt;TD&gt;&lt;FONT face=Garamond size=3&gt;Web services technology is rapidly evolving creating endless opportunities for user participation. These developments are providing multitude of possibilities for hackers to compromise web applications. This raises several security concerns in the realm of Web Application Security. The approach outlined in this paper attempts to address these security concerns. Pragmatically speaking, the company brand name can be protected at a reasonable cost in few simple steps to ensure Web Application Security. This can minimize the chances of CIO’s phone ringing in the midnight for “web security stuff”.&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;UL&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;BR&gt;&amp;nbsp;&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Pragmatic Web Application Security - Part 8 - Technical Controls</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2009/3/19/4127734.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2009/3/19/4127734.html</guid>
    <pubDate>Thu, 19 Mar 2009 07:07:57 -0700</pubDate>
    <description>&lt;FONT face=Garamond size=4&gt;It is not within the scope of this paper to address the gory details of Technical Controls. Technical controls can ensure the security of web applications. Some of the recommended technical controls for Web Application Security are:&lt;/FONT&gt; 
&lt;UL type=DISC&gt;
&lt;LI&gt;&lt;FONT size=4&gt;&lt;FONT face=Garamond&gt;Firewall, IDS/IPS&lt;/FONT&gt; &lt;/FONT&gt;
&lt;LI&gt;&lt;FONT size=4&gt;&lt;FONT face=Garamond&gt;Hardened OS&lt;/FONT&gt; &lt;/FONT&gt;
&lt;LI&gt;&lt;FONT size=4&gt;&lt;FONT face=Garamond&gt;Hardened Web Server&lt;/FONT&gt; &lt;/FONT&gt;
&lt;LI&gt;&lt;FONT size=4&gt;&lt;FONT face=Garamond&gt;DMZ Architecture&lt;/FONT&gt; &lt;/FONT&gt;
&lt;LI&gt;&lt;FONT size=4&gt;&lt;FONT face=Garamond&gt;Design of High Availability (at the least 99.99% uptime)&lt;/FONT&gt; &lt;/FONT&gt;
&lt;LI&gt;&lt;FONT size=4&gt;&lt;FONT face=Garamond&gt;Access Control for Applications&lt;/FONT&gt; &lt;/FONT&gt;
&lt;LI&gt;&lt;FONT size=4&gt;&lt;FONT face=Garamond&gt;Encryption for Sensitive Data&lt;/FONT&gt; &lt;/FONT&gt;
&lt;LI&gt;&lt;FONT size=4&gt;&lt;FONT face=Garamond&gt;Web Application Firewall&lt;/FONT&gt; &lt;/FONT&gt;
&lt;LI&gt;&lt;FONT size=4&gt;&lt;FONT face=Garamond&gt;Source Code Scanning&lt;/FONT&gt; &lt;/FONT&gt;
&lt;LI&gt;&lt;FONT size=4&gt;&lt;FONT face=Garamond&gt;SAS 70 Certified Datacenter Infrastructure&lt;/FONT&gt; &lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;FONT size=4&gt;&amp;nbsp;
&lt;P&gt;&lt;FONT face=Garamond size=4&gt;It is desirable for an ASP to have these controls in place. Preferably, controls such as IDS/IPS should be in place, but they are not mandatory. Same is the case with Web Application Firewall.&lt;/FONT&gt;&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Pragmatic Web Application Security - Part 7 - Education/Awareness</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2009/3/17/4126098.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2009/3/17/4126098.html</guid>
    <pubDate>Tue, 17 Mar 2009 07:04:07 -0700</pubDate>
    <description>&lt;P&gt;&lt;FONT face=Garamond&gt;The importance of Security Awareness and Education cannot be downplayed.&lt;/FONT&gt; &lt;/P&gt;
&lt;P&gt;&lt;FONT face=Garamond size=3&gt;Human element is the weakest element in security. In Step 2, we created policies. It is important that relevant team members are well aware of the security policies. The relevant team members should have the knowledge of company’s Information Classification policy, without this “Sensitive Data” is at risk of being handled incorrectly. A fortune 500 company had Content Publishers who were managing the content without the knowledge of Information Classification Policy. Content Publishers uploaded some sensitive content in the publishing area. The publish software program copied the sensitive content to the production website. This exposed company’s sensitive information on the public Internet till this was noticed by an external party, who ended up alerting the company CIO. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;FONT face=Garamond size=3&gt;To ensure proper data handling Awareness and Education is very important. &lt;/FONT&gt;&lt;/P&gt;
&lt;UL type=DISC&gt;
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;Content publishers should have the knowledge of Information Classification Policy&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;Project Managers should have knowledge of Policy for auditing ASPs&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;Website Administrators and Infrastructure Administrators should have the knowledge of Policy of Hosting Websites and follow the guidelines outlined in the policy.&lt;/FONT&gt; &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;FONT face=Garamond size=3&gt;In dealing with ASPs, it can be verified that they have a well defined policies in these areas during ASP Audit itself. Moreover, Project Managers should communicate to the ASP the sensitivity of the data on the website and its handling requirements.&amp;nbsp; These items can be addressed in the Services Agreement if warranted.&lt;/FONT&gt;&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Pragmatic Web Application Security - Part 6 - Vulnerability Assessment and Remediation</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2009/3/16/4125066.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2009/3/16/4125066.html</guid>
    <pubDate>Mon, 16 Mar 2009 07:07:51 -0700</pubDate>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=4&gt;&lt;FONT face=Garamond&gt;This involves two components. The Host Vulnerability Scanning and the Application Vulnerability Scanning. Multitude of tools exists in the market that can do Host Vulnerability Scanning - nCircle is one of them.&lt;/FONT&gt; &amp;nbsp;&amp;nbsp; &lt;/FONT&gt;
&lt;P&gt;&lt;FONT face=Garamond size=4&gt;For Application Vulnerability Scanning there are many players out there such as Watchfire. Many of these players find the usual vulnerabilities in the application. Outsourced application security vendors such as WhiteHat not only find typical application vulnerabilities but also find application business logic errors.&lt;/FONT&gt;&lt;/P&gt;&lt;FONT size=4&gt;&lt;FONT face=Garamond&gt;Vulnerability assessment will yield a list of vulnerabilities. Ranking these vulnerabilities is a good starting point. The vulnerabilities should be ranked based on Severity Level and Threat Level. Threat is the likelihood of the vulnerability being exploited and severity is how bad it can affect if vulnerability is realized.&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;
&lt;P&gt;&lt;FONT face=Garamond size=4&gt;The Web Developers need to be competent to remediate these vulnerabilities. This can happen through only through proper training.&amp;nbsp; Secure Software Development methodology helps build secure web application ground up.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=4&gt;&lt;FONT face=Garamond&gt;Apart from fixing these vulnerabilities, Web&amp;nbsp;Developers have other priorities. Their schedule needs to be respected and deal with them tactfully to&amp;nbsp;remediate vulnerabilities.&amp;nbsp;Some of these vulnerabilities are inter-dependent. Remediation of a single vulnerability, could remediate several other vulnerabilities.&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;
&lt;P&gt;&lt;FONT face=Garamond size=4&gt;Vulnerabilities can be integrated into an already existing bug tracking system under category security. Web Developers can&amp;nbsp;remediate these&amp;nbsp;bugs along with other bugs. This approach relieves the workload of tracking security vulnerabilities separately.&lt;/FONT&gt;&lt;/P&gt;&lt;FONT size=4&gt;&lt;FONT face=Garamond&gt;For ASP hosted website, there is limited visibility into their web development process. Before you perform a vulnerability assessment on ASP website, ensure that you have consent from them in the form of a legal agreement. Performing a vulnerability assessment (or a scan) without their consent could lead to legal ramifications. The author had made a mistake of performing application vulnerability scan on an ASP, speculating that it would not be too much of load on their site. Unfortunately, the scanner behaved weirdly, causing a flood of traffic to the ASP website. The ASP was not happy, luckily for the author, ASP let the problem resolve in a peaceful way else this could have lead to legal ramifications.&lt;/FONT&gt;&amp;nbsp;
&lt;P&gt;&lt;FONT face=Garamond size=4&gt;Performing a Security Audit on ASP can help address some concerns. During the Security Audit, we can request ASP to provide Application Vulnerability Scan Report and/or Host Vulnerability Scan report if they already have one. In some situations, this can relieve us from the coordinating with the ASP to perform a vulnerability scan report ourselves.&lt;/FONT&gt;&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Pragmatic Web Application Security - Part 5 - Create  Policies</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2009/3/13/4121670.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2009/3/13/4121670.html</guid>
    <pubDate>Fri, 13 Mar 2009 07:05:35 -0700</pubDate>
    <description>&lt;TABLE width=631&gt;
&lt;TBODY&gt;
&lt;TR vAlign=top&gt;
&lt;TD&gt;&lt;FONT face=Garamond size=3&gt;Creating a policy is relatively easy compared to enforcing a policy. There needs to be a standard policies for:&lt;/FONT&gt; 
&lt;UL type=DISC&gt;
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;Policy for Hosting Websites&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;Policy for Auditing ASPs&lt;/FONT&gt; &lt;/LI&gt;&lt;/UL&gt;&lt;FONT face=Garamond size=3&gt;&lt;STRONG&gt;Policy for Hosting Websites:&lt;/STRONG&gt; The objective is to set security requirements for the company’s external websites that are accessible over the public Internet. This policy should apply to all websites whether it is hosted by the company or it is hosted by an ASP. As an example: Some of the standards in the policy can be:&lt;/FONT&gt; 
&lt;UL type=DISC&gt;
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;All content will be thoroughly reviewed to identify sensitivity of data before being published&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;Personnel responsible for publishing the content shall be adequately trained in the company’s Information Classification Policy, so that they are aware of data handling requirements&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;Technical standards for infrastructure and web servers&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;Secure development of web application&lt;/FONT&gt; &lt;/LI&gt;&lt;/UL&gt;&amp;nbsp;&lt;FONT face=Garamond size=3&gt;&lt;STRONG&gt;Policy for Auditing ASPs:&lt;/STRONG&gt; The objective is to set requirements for ASPs to handle company’s data. Some of the requirements can be:&lt;/FONT&gt; 
&lt;UL type=DISC&gt;
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;Well articulated Information Security Policy&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;Infrastructure requirements&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;Data handling requirements&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;Application security requirements&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;Availability requirements&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;Personnel requirements&lt;/FONT&gt; &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;FONT face=Garamond size=3&gt;The policy needs to be well articulated and communicated to the relevant team members. This will set a reference point for expectation in terms of Web Application Security.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;UL&gt;
&lt;/UL&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Pragmatic Web Application Security - Part 4 - Plan for Web Application Security</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2009/3/11/4119238.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2009/3/11/4119238.html</guid>
    <pubDate>Wed, 11 Mar 2009 07:05:38 -0700</pubDate>
    <description>&lt;TABLE width=631&gt;
&lt;TBODY&gt;
&lt;TR vAlign=top&gt;
&lt;TD&gt;&lt;FONT face=Garamond size=3&gt;Websites run web applications. It is important to understand what is at stake in this exercise. The first step is to gather a list of company’s Internet facing websites. These sites can be of two types:&lt;/FONT&gt; 
&lt;UL type=DISC&gt;
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;Company Hosted&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;ASP (&lt;strong&gt;A&lt;/strong&gt;pplication &lt;strong&gt;S&lt;/strong&gt;ervice &lt;strong&gt;P&lt;/strong&gt;rovider) Hosted&lt;/FONT&gt; &lt;/LI&gt;&lt;/UL&gt;&amp;nbsp;&lt;FONT face=Garamond size=3&gt;The next step is to identify types of data these websites have. Now we have 4 different classification levels:&lt;/FONT&gt;
&lt;UL type=DISC&gt;
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;Company Hosted with Sensitive Data&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;Company Hosted with Public Data&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;ASP Hosted with Sensitive Data&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=3&gt;ASP Hosted with Public Data&lt;/FONT&gt; &lt;/LI&gt;&lt;/UL&gt;&amp;nbsp;&lt;FONT face=Garamond size=3&gt;The Table below gives a summary of websites and controls that should be in place to ensure Web Application Security:&lt;/FONT&gt;&amp;nbsp;&lt;BR&gt;
&lt;DIV align=left&gt;
&lt;TABLE cellSpacing=0 width=501 border=2&gt;
&lt;TBODY&gt;
&lt;TR vAlign=top&gt;
&lt;TD bgColor=#ccffcc height=6&gt;&lt;FONT face=Garamond size=2&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;strong&gt;Hosting Model&lt;/strong&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ccffcc rowSpan=2&gt;&lt;FONT face=Garamond size=2&gt;Company Hosted &lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ccffcc rowSpan=2&gt;&lt;FONT face=Garamond size=2&gt;ASP Hosted &lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR vAlign=top&gt;
&lt;TD bgColor=#ffcc99 height=6&gt;&lt;FONT face=Garamond size=2&gt;&lt;strong&gt;Data Type&lt;/strong&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR vAlign=top&gt;
&lt;TD bgColor=#ffcc99&gt;&lt;FONT face=Garamond size=2&gt;Sensitive&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT face=Garamond size=2&gt;&lt;strong&gt;Objective: &lt;/strong&gt;Ensure Confidentiality, Integrity and Availability&lt;/FONT&gt; 
&lt;UL type=DISC&gt;
&lt;LI&gt;&lt;FONT face=Garamond size=2&gt;Service Level Agreement with Internal Web&amp;nbsp; Dept&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=2&gt;Application Vulnerability Assessment &lt;/FONT&gt;
&lt;LI&gt;&lt;FONT face=Garamond size=2&gt;Access Control&lt;/FONT&gt; &lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT face=Garamond size=2&gt;&lt;strong&gt;Objective: &lt;/strong&gt;Ensure Confidentiality, Integrity and Availability&lt;/FONT&gt; 
&lt;UL type=DISC&gt;
&lt;LI&gt;&lt;FONT face=Garamond size=2&gt;ASP Audit&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=2&gt;Master Service Agreement and Service Level Agreement with ASP&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=2&gt;Application Vulnerability Assessment with ASP’s involvement (if needed)&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=2&gt;Access Control&lt;/FONT&gt; &lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR vAlign=top&gt;
&lt;TD bgColor=#ffcc99 height=75&gt;&lt;FONT face=Garamond size=2&gt;Public&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT face=Garamond size=2&gt;&lt;strong&gt;Objective: &lt;/strong&gt;Ensure Integrity and Availability&lt;/FONT&gt; 
&lt;UL type=DISC&gt;
&lt;LI&gt;&lt;FONT face=Garamond size=2&gt;Service&amp;nbsp;Level Agreement with Web Dept&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=2&gt;Application Vulnerability Assessment&lt;/FONT&gt; &lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT face=Garamond size=2&gt;&lt;strong&gt;Objective: &lt;/strong&gt;Ensure Integrity and Availability&lt;/FONT&gt; 
&lt;UL type=DISC&gt;
&lt;LI&gt;&lt;FONT face=Garamond size=2&gt;ASP Audit&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=2&gt;Master Service Agreement and Service Level Agreement with ASP&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Garamond size=2&gt;Application Vulnerability Assessment with ASP’s involvement (if needed)&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&amp;nbsp;&lt;BR&gt;&amp;nbsp;&lt;FONT face=Garamond size=3&gt;Identify sites that are in scope based on criticality of website for the business. A simple way to do this is by asking: What will happen if this website goes down for a day? The available &lt;strong&gt;budget &lt;/strong&gt;to implement the plan sets the upper limit for in scope websites.&lt;/FONT&gt;&amp;nbsp;&lt;BR&gt;
&lt;P&gt;&lt;FONT face=Garamond size=3&gt;Identify relevant team membersfor Company Hosted websites: Sponsors, Project Managers, Content Publishers, Web Administrators and Infrastructure/System Administrators.&lt;/FONT&gt;&lt;/P&gt;&amp;nbsp;&lt;FONT face=Garamond size=3&gt;Identify relevant team members for ASP Hosted websites: Sponsors, Company Project Managers, ASP Contact Information such ASP Project Managers, ASP Security Architect and ASP Infrastructure/System Administrators.&lt;/FONT&gt;&amp;nbsp;&lt;BR&gt;
&lt;P&gt;&lt;FONT face=Garamond size=3&gt;This inventory will empower with knowledge to carry out the next steps pragmatically.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Pragmatic Web Application Security - Part 3 -  Web Application Security?</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2009/3/10/4118226.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2009/3/10/4118226.html</guid>
    <pubDate>Tue, 10 Mar 2009 07:10:00 -0700</pubDate>
    <description>&lt;FONT size=4&gt;&lt;FONT face=Garamond&gt;Applications are&amp;nbsp;catalyst to our day to day business function. Application that is accessible via the Browser is also known as Web Application. With the advent of Web 2.0 which provides user centric (also collaborative) web based services, users are gaining more control on web applications. This enhanced control provides more possibilities for hackers to exploit Web Application. One recent example of sophisticated Web 2.0 attack vector is the feed injection. &lt;/FONT&gt;&amp;nbsp; 
&lt;P&gt;&lt;FONT face=Garamond size=4&gt;Web Application Security is ensuring of confidentiality, integrity and availability of Web Applications.&amp;nbsp; &lt;/FONT&gt;&lt;A href=&quot;http://www.webappsec.org/projects/threat/&quot; target=_blank&gt;&lt;FONT face=Garamond color=#0000ff size=4&gt;&lt;U&gt;Web Application Security Consortium&lt;/U&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Garamond size=4&gt; has excellent resources in this domain. The attack class can vary from a simple “Directory Indexing” to a complicated “Cross-site scripting”.&lt;/FONT&gt;&lt;/P&gt;&lt;FONT size=4&gt;&amp;nbsp;&lt;FONT face=Garamond&gt;Any Web Application Security Plan has to be practical. A company can have hundreds of websites (Internal or External) hence it is not possible to bring all the sites under this plan hence it is a good idea to define the scope. In this document, focus is on the websites facing the Internet. Many companies have “Turtle” model of security. Turtle model of security is &lt;STRONG&gt;hard shell exterior &lt;/STRONG&gt;and &lt;STRONG&gt;soft chewy interior&lt;/STRONG&gt;. The essence of the model is a company does not trust folks coming from outside, hence perimeter is protected with Firewall/IDS/IPS. Internal workforce is trusted not to cause information security breach – this sounds idealistic but that is the reality in many companies. Once you are inside you pretty much can lay hands on anything. Web applications inside the shell are considered off limits from hackers. Web applications outside the shell or in DMZ are considered vulnerable.&lt;/FONT&gt;&amp;nbsp; 
&lt;P&gt;&lt;FONT face=Garamond size=4&gt;The focus of the article&amp;nbsp;is Web Application Security of Internet facing websites. Same methodology can be applied to the Internal websites with some tweaking.&amp;nbsp;In my next blog post I narrate&amp;nbsp;a pragmatic four steps plan to ensure Web Application Security.&lt;/FONT&gt;&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Pragmatic Web Application Security Part 2 - Act to Protect Brand</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2009/3/9/4117232.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2009/3/9/4117232.html</guid>
    <pubDate>Mon, 09 Mar 2009 07:04:12 -0700</pubDate>
    <description>&lt;FONT size=4&gt;&lt;FONT face=Garamond&gt;Doing nothing is not an acceptable solution. If the Wayne,&amp;nbsp;Information Security Manager does not come up with a Web Application Security plan, similar Hot seat incidents are likely to&amp;nbsp;recur and can tarnish the brand image. Moreover, it can cause significant Business Risk and Business Impact.&lt;/FONT&gt; &amp;nbsp;
&lt;P&gt;&lt;FONT face=Garamond size=4&gt;Brand damage can hurt company’s market capitalization. It is well known that any bad news can hurt company’s market capitalization from 3-10%. A billion dollar company can take a hit of several million dollars in market capitalization as a result of bad publicity from a security breach.&lt;/FONT&gt;&lt;/P&gt;&lt;FONT size=4&gt;&amp;nbsp;&lt;FONT face=Garamond&gt;Perception is everything. Customers perceive company’s online identity through their strong presence on the web. Customer stumbling upon poor web application design such as an error page spewing the gory details of the website’s back end database will spoil customer experience and affect company’s identity.&lt;/FONT&gt;&amp;nbsp;
&lt;P&gt;&lt;FONT face=Garamond size=4&gt;Moreover, customers constantly make assessment of company’s identity before doing business with a company. Customer will not do business with a company whose information security practices are viewed as unreliable. Customers may scale down or even stop, transacting with companies whose security practices are viewed poorly.&lt;/FONT&gt;&lt;/P&gt;&lt;FONT size=4&gt;&amp;nbsp;&lt;FONT face=Garamond&gt;Web applications accessible over the Internet are highly visible to customers and to public. On a similar note it is accessible to hackers who are out there to exploit any opportunity that shall be presented due to negligence or lack of planning in deploying these websites.&amp;nbsp;&lt;/FONT&gt;&amp;nbsp;
&lt;P&gt;&lt;FONT face=Garamond size=4&gt;There could be a revenue impact due to security breach of eCommerce website. Customers may not want to do business with a company over the web. Moreover, these sites could hold sensitive customer data. Breaching customer data can put a company in a world of legal ramifications. &lt;/FONT&gt;&lt;/P&gt;&lt;FONT size=4&gt;&amp;nbsp;&lt;FONT face=Garamond&gt;Hackers are becoming more professional. Their attacks are not motivated by ego as was the case in the past, but more by economic gains. Their attacks are refined and are more focused on access to sensitive data behind the applications. They use the sensitive data for economic gains.&lt;/FONT&gt;&amp;nbsp;
&lt;P&gt;&lt;FONT face=Garamond size=4&gt;Doing nothing is not an option here. Company has to act wisely to secure its website to protect its brand.&lt;/FONT&gt;&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Pragmatic Web Application Security - Part 1 -  Hot Seat</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2009/3/6/4114666.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2009/3/6/4114666.html</guid>
    <pubDate>Fri, 06 Mar 2009 07:06:00 -0800</pubDate>
    <description>&lt;TABLE width=631&gt;
&lt;TBODY&gt;
&lt;TR vAlign=top&gt;
&lt;TD&gt;
&lt;H5&gt;&amp;nbsp;&lt;/H5&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT face=Garamond size=3&gt;World Wide Web has evolved from a document sharing tool to highly interactive platform where software applications can be offered as a service – SaaS (Software as a Service). The users have a more control on the web than in the Web 1.0 due to collaborative nature of Web 2.0 platform of Web 2.0. This has opened possibilities for hackers to exploit web applications. This&amp;nbsp;series&amp;nbsp;of articles&amp;nbsp;provides a practical approach in finding a solution to Web Application Security concerns.&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;DIV align=left&gt;
&lt;TABLE width=631&gt;
&lt;TBODY&gt;
&lt;TR vAlign=top&gt;
&lt;TD&gt;
&lt;H5&gt;&amp;nbsp;&lt;/H5&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT face=Garamond size=3&gt;This&amp;nbsp;audience is intended for Information Security Managers who are responsible for implementing web application security. Hope you enjoy the narratives that follow!&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;
&lt;DIV align=left&gt;
&lt;TABLE width=631&gt;
&lt;TBODY&gt;
&lt;TR vAlign=top&gt;
&lt;TD&gt;
&lt;H5&gt;&lt;FONT face=Garamond size=3&gt;&lt;STRONG&gt;
&lt;TABLE width=631&gt;
&lt;TBODY&gt;
&lt;TR vAlign=top&gt;
&lt;TD&gt;&lt;FONT face=Garamond size=3&gt;It was around 1:00am. The phone is ringing. Steve, the CIO had a stressful previous day working on a plan for next year’s roadmap.&amp;nbsp;Steve hardly had about an hour of sleep; the sound of the phone ring is bothering him. In a semi wake state he gets out of bed to answer the phone wishing it was a misdialed call. It is the&amp;nbsp;Roger, CEO at the other end.&amp;nbsp;Roger was notified by an Analyst that the public ftp website of the company contains offensive and objectionable content.&amp;nbsp;Roger tells&amp;nbsp;Steve to do whatever it takes to bring the situation back to normal.&amp;nbsp;Steve is worried about the company brand name.&lt;/FONT&gt; &amp;nbsp;&lt;BR&gt;
&lt;P&gt;&lt;FONT face=Garamond size=3&gt;Steve hangs up the phone. He dials&amp;nbsp; Wayne, the Information Security Manager. In an&amp;nbsp;apparent upset tone, he instructs&amp;nbsp;Wayne to get the situation back to normal and provide with regular updates.&amp;nbsp;Wayne&amp;nbsp;calls Tim, the&amp;nbsp;Information Security&amp;nbsp;Lead and asks him to act on this.&lt;/FONT&gt;&lt;/P&gt;&lt;FONT face=Garamond size=3&gt;Tim &amp;nbsp;springs into action, sets up a conference call with the ftp&amp;nbsp;website&#39;s project Manager and other relevant team members. The conference call was boisterous with lots of finger pointing. Finally, they all agree on an action plan. As a part of remediation the website Project Manager instructs&amp;nbsp;web&amp;nbsp;publishers&amp;nbsp;to remove the offensive content from the web server. The Project Manager requests the web operations team to secure the ftp webserver to ensure the security holes are plugged in.&amp;nbsp;&lt;/FONT&gt;&amp;nbsp;&lt;FONT face=Garamond size=3&gt;Around 5:00am, remediation is complete. The knee jerk reaction is over and there is an ensuing calm after the storm. CIO’s phone rings around 7:00am, he picks up the phone, he is feeling better after some decent sleep, and he sounds somewhat pleasant over the phone. Wayne&amp;nbsp;informs that the incident has been remediated and the offensive content has been removed. The CIO says: Great! But, What is your long term plan for the security of web stuff?&lt;/FONT&gt; 
&lt;P&gt;&lt;FONT face=Garamond size=3&gt;&lt;BR&gt;Hmmm.. Security of web stuff,&amp;nbsp;Wayne&amp;nbsp;goes into thinking mode. How do I go about this? I do know the solution has to be practical and realistic for my budget. There are several hundreds of internal websites and about several dozens external websites. Where do I start? Let me present this challenge to Tim to come up with an action plan.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P&gt;&lt;BR&gt;&amp;nbsp;&lt;/P&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H5&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Information security in bad economy</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2008/10/26/3948897.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2008/10/26/3948897.html</guid>
    <pubDate>Sun, 26 Oct 2008 19:37:40 -0700</pubDate>
    <description>&lt;P&gt;Economy looks grim. The headlines are very discouraging. Capitalism does not guarantee wealth and success all the time. The talking heads on TV blame the&amp;nbsp;greed in the stock market. I wish stock market is made of just computers that are not greedy human beings. These are bound to happen when there are human beings that participate! Money flows will eventually correct itself&amp;nbsp; I hope, capitalism will be healthy again. This will take time. I am not an economist, but I do understand that people part with money for a period of time to collect higher return in the horizon based on their aptitude for risk.&amp;nbsp; Simple is it not! But, all these complex financial instruments and its machinations seem to blur the reality and make even the brainiest act dumb - or are they just plain greedy?&lt;/P&gt;
&lt;P&gt;Setting the context for this post, it is a tough economic situation all over the world. IT spending has reduced and will reduce significantly. In one of earlier posts, I&amp;nbsp;had referred&amp;nbsp;to information security as an overhead of an overhead (IT).&amp;nbsp;What is a good approach for&amp;nbsp;security practice in this type of economy? &lt;/P&gt;
&lt;P&gt;I don&#39;t have a magic wand to pull a rabbit out of a hat. I have always been told&amp;nbsp;that: tough economy is the time for&amp;nbsp;real smart people to&amp;nbsp;make money. Coming back to information security topic,&amp;nbsp;with a bit of common sense, it is wise for&amp;nbsp;information security professionals to offer services in&amp;nbsp;those&amp;nbsp;areas&amp;nbsp;that does not involve capital expenditure. As a Security Manager, you may be already aware that your people are willing to&amp;nbsp;go&amp;nbsp;an extra mile in the current economic times.&lt;/P&gt;
&lt;P&gt;- No budget or lack of budget,&amp;nbsp;means no&amp;nbsp;new capital expenditure. Spend time wisely in building a future technology strategy and keep it in the back pocket when the economy turns around.&lt;/P&gt;
&lt;P&gt;- This is a good time to create roles/responsibilities and ownership for various areas. Create operating procedures.&amp;nbsp;Make your team to automate tasks. This will help your operations become more efficient.&lt;/P&gt;
&lt;P&gt;- This is time for security awareness&amp;nbsp; education. Create pamphlets/brochures/presentations for an online or classroom training. Engage your and your team&#39;s time to impart training.&lt;/P&gt;
&lt;P&gt;- Leverage already invested&amp;nbsp;technology platforms. Leverage utilized features that reduce costs. If you have already invested in technology such as VMware, this is the time to get the best out of it. You can use VMware&#39;s toolkit to build your lab and staging&amp;nbsp;environment and optimize on hardware cost.&lt;/P&gt;
&lt;P&gt;- Off shoring has been the mantra of senior executives, this is the time to revisit those services and measure their performance closely&amp;nbsp;and assess&amp;nbsp;your satisfaction level. This is a good time to build a case for not off shoring if it makes sense.&lt;/P&gt;
&lt;P&gt;- Companies are more vulnerable in bad economic times. You are in a better position&amp;nbsp;to&amp;nbsp;influence senior management about information security risks under these circumstances and drive home the value of protecting your intellectual property under these kinds of circumstances. management will be all ears&amp;nbsp;for such a pitch.&lt;/P&gt;
&lt;P&gt;- Time to engage your architect to optimize your security architecture, revisit standards and optimize design for cost efficiency.&lt;/P&gt;
&lt;P&gt;- Revisit various controls and see if there are some risks that you could optimize spending on.&lt;/P&gt;
&lt;P&gt;- Training budget&amp;nbsp;is an unfortunate victim of&amp;nbsp;this type of economy. Encourage employees to take free webinars offered by various security vendors and encourage them to share the summary across the team. This will put your employees in touch with latest happenings in security at the same time there is some learning that is imparted&amp;nbsp;despite&amp;nbsp;zero training budget.&lt;/P&gt;
&lt;P&gt;- Since there are very few projects in action, this is a good time to have conversations with cross functional teams and educate them about your services and solicit feedback on how to do better.&lt;/P&gt;
&lt;P&gt;- Revisit your vendor logistics and identify whether you can renegotiate some of your already existing contracts.&lt;/P&gt;
&lt;P&gt;The above are some good&amp;nbsp;ways by which you can optimize costs, this will also enhance&amp;nbsp;your team&#39;s competence level in the long run. And this approach is better than letting people go, if you can pull this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Building secure application</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2008/10/2/3912084.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2008/10/2/3912084.html</guid>
    <pubDate>Thu, 02 Oct 2008 06:35:44 -0700</pubDate>
    <description>&lt;P&gt;&lt;IMG style=&quot;WIDTH: 434px; HEIGHT: 369px&quot; height=404 src=&quot;http://ravichar.blogharbor.com/developer.bmp&quot; width=604&gt;&lt;/P&gt;
&lt;P&gt;Developers have the objective of building a functional application. They are focused on building more functionality&amp;nbsp;into applications. Moreover, building security creates more workload&amp;nbsp; for Developers which is a disincentive and moreover,&amp;nbsp;Developers are&amp;nbsp;rewarded for building more functionality than building more security. I have never seen a Developer in my professional life for being rewarded for building a secure application.&lt;/P&gt;
&lt;P&gt;Hackers are focused on how to break the application. They look for weak links in application that will enable them to access application data. Developers usually follow process to build application, but Hackers have no process and all they have is multitude of possibilities.&amp;nbsp;Hackers are innovative in trying various permutations in compromising the application. &lt;/P&gt;
&lt;P&gt;A million dollar&amp;nbsp;question is whether we can&amp;nbsp;build secure applications when a Developer&amp;nbsp;is focused on functionality&amp;nbsp;but not on breaking the application?&lt;/P&gt;
&lt;P&gt;There is a school of thought about Inside-out security where the application is built securely from scratch. Unfortunately,&amp;nbsp; this approach won&#39;t suffice because hackers traverse Outside-in. A little reflection will&amp;nbsp;highlight the importance of&amp;nbsp;vulnerability scanning and&amp;nbsp;penetration testing of application. This will bring the perspective of what developers do not know already.&lt;/P&gt;
&lt;P&gt;Building a secure application inside out is not enough. In order to address unknown unknowns (or blind spots of developers), penetration testing should be done.&amp;nbsp;Both whitebox style penetration testing (where components of an application is known)&amp;nbsp; and also blackbox style penetration&amp;nbsp;testing which mi micks an Hacker who may not have any knowledge of the application, should be carried out.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;An application of higher level of security is not built just by Developers. It is&amp;nbsp;built by integrative&amp;nbsp;process&amp;nbsp;of Developer&amp;nbsp;mindset&amp;nbsp;and Hacker mindset.&amp;nbsp;&amp;nbsp;This is a constant struggle for years to come.&lt;BR&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>The asymmetry of data loss - data thief has an upper hand</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2008/10/1/3910766.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2008/10/1/3910766.html</guid>
    <pubDate>Wed, 01 Oct 2008 06:33:22 -0700</pubDate>
    <description>&lt;P&gt;I read this&amp;nbsp;awesome book by Dan Geer, &lt;A href=&quot;http://www.verdasys.com/thoughtleadership/&quot;&gt;Economics and Strategies of Data Security&lt;/A&gt;. This gave me structure&amp;nbsp;for my thoughts about a complex topic such as data security. &lt;/P&gt;
&lt;P&gt;When&amp;nbsp;a&amp;nbsp;data owner&#39;s (a business)&amp;nbsp;sensitive data is breached it is&amp;nbsp;difficult to quantify the monetary loss. According to respectable survey sources, the average cost of sensitive data breach for a large size company is about $50,000. I am attempting here to think about this in simple mathametical terms:&lt;/P&gt;
&lt;P&gt;There is a data breach. From the data owner&#39;s perspective the loss is:&lt;/P&gt;
&lt;P&gt;&lt;FONT color=#3366ff&gt;Loss&amp;nbsp;= Cost to protect data&amp;nbsp;+ Loss of business due to data theft aka cost of competitive disadvantage&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;From the data thief&#39;s perspective&lt;/P&gt;
&lt;P&gt;&lt;FONT color=#3333ff&gt;Net Gain= [Cost of producing the data&amp;nbsp; *&amp;nbsp; Data freshness factor] - Cost to steal the data + Profit of business due to data aka gain of competitive advantage&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;From the above two equations it is very clear that this is not a zero sum game. There is a clear cost asymmetry for a data owner and for a data thief. When there is an asymmetry there is an opportunity. Data owner&amp;nbsp;would not even know that the&amp;nbsp;data is lost because&amp;nbsp;the original copy of the data may be still intact - data thief could have simply copied the data.&amp;nbsp;Data theft does not look like&amp;nbsp;a car theft, there is no vacuum left behind.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;This motivates a data thief to keep the cost to steal low, steal highly valuable data that has&amp;nbsp;a long shelf life and in a way that data owner will never even be aware of theft.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;From&amp;nbsp;a data thief&#39;s perspective, the cost to steal data if kept high would disincentive him. Moreover, Data freshness factor, i.e. how valuable this data is over period of time plays an important role.&amp;nbsp;A good example is content of today&#39;s newspaper is hardly valuable tomorrow, but the content of newspaper two days ahead (if can be procured)would be invaluable. Data relevance is a function of time and other marketplace variables - &amp;nbsp;Data freshness Factor accounts for that variable. A good way to discourage data thief is to increase his/her cost to steal the data. There are other inferences from the above equation. If there exists&amp;nbsp;no competitive advantage&amp;nbsp;with the stolen data, hardly any thief would even venture&amp;nbsp;to steal the&amp;nbsp;data in the first place. If the cost of producing data is very low, then probably thief can just produce the data himself and would not attempt to steal the data. If the cost of&amp;nbsp;theft is kept high, it would definitely deter the data thief from stealing data using technical mechanisms, then the data thief would&amp;nbsp;exploit weak links in data security&amp;nbsp;such as use of social engineering to get access to the data.&lt;/P&gt;
&lt;P&gt;From data owner perspective protecting data becomes very important. How much would the owner be willing to spend? Not definitely the cost equal to cost of producing the data. 1% to 10% of cost of producing data is considered prudent. For a data owner it is difficult to estimate cost of data protection of a specific data, because it is not easy to chunkify data protection costs. Moreover, as Dan Geer says in his book, a data owner has to protect himself from number of intruders not just one.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;It pays for a data owner to: be aware of data breaches (or data leaks), employ appropriate&amp;nbsp;mechanisms to protect the data; the cost of protection which&amp;nbsp;is fractional cost of&amp;nbsp;the valuable&amp;nbsp;data and&amp;nbsp;enhance information security awareness of personnel who handle the data.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Data loss is not a zero sum game. The advantage is in favor of a data thief (data thieves rather).&amp;nbsp;Data owner does not give much thought&amp;nbsp;on&amp;nbsp;the value of data&amp;nbsp;unless&amp;nbsp;there is a data theft.&amp;nbsp;But,&amp;nbsp;a&amp;nbsp;data thief&amp;nbsp;has every reason to think about economics of data theft before he acts to steal the data else data thief won&#39;t survive in this game and he is very well aware of his advantageous position.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Misc notes on IDS/IPS</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2008/9/28/3905240.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2008/9/28/3905240.html</guid>
    <pubDate>Sun, 28 Sep 2008 20:11:06 -0700</pubDate>
    <description>&lt;P&gt;Chris Hoff&#39;s response on his blog &lt;A href=&quot;http://rationalsecurity.typepad.com/&quot;&gt;Rational Survivability&lt;/A&gt; makes me happy on&amp;nbsp;two fronts. The primary reason I started this blog was to use this medium as an outlet for my ungrounded ego. The other&amp;nbsp;was&amp;nbsp;to participate in the Security Blogging community which was then catching up when I started&amp;nbsp; this blog 2 years ago. To get a response for my musings from&amp;nbsp;brilliant minds&amp;nbsp;such as Mike Rothman, Alan Shimel, Chris&amp;nbsp;Hoff and others,&amp;nbsp;gives me immense joy. May be this a good therapy for my undiagnosed attention deficit.&lt;/P&gt;
&lt;P&gt;It does not matter if Chris is right or I am right. The outcome of IDS/IPS&amp;nbsp;is all determined by random drift of market forces. There is no conspiracy&amp;nbsp;to make IDS/IPS this way or that way.&amp;nbsp;I would like to wrap up with a quote from Arthur Chandler : &quot;We can tell when a technology has truly arrived when the new problems it gives rise&amp;nbsp; to approach in magnitude the problem it was designed to solve&quot;.&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Please contact Microsoft for Firefox problem?  True but Funny Dialog Box</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2008/9/25/3901057.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2008/9/25/3901057.html</guid>
    <pubDate>Thu, 25 Sep 2008 06:23:47 -0700</pubDate>
    <description>&lt;P&gt;&lt;SPAN class=521220116-25092008&gt;&lt;FONT face=Garamond&gt;&lt;SPAN class=521220116-25092008&gt;&lt;FONT face=Garamond&gt;&lt;SPAN class=521220116-25092008&gt;&lt;FONT face=Garamond&gt;&lt;SPAN class=521220116-25092008&gt;&lt;FONT face=Garamond&gt;&lt;IMG src=&quot;http://ravichar.blogharbor.com/dialog.bmp&quot;&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>IDS/IPS - is it Vitamins?</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2008/9/24/3899861.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2008/9/24/3899861.html</guid>
    <pubDate>Wed, 24 Sep 2008 18:35:22 -0700</pubDate>
    <description>&lt;P&gt;Alan Shimel&#39;s post on&amp;nbsp; &quot;&lt;A href=&quot;http://www.stillsecureafteralltheseyears.com/ashimmy/idsips/index.html&quot;&gt;IDS - the beast that just won&#39;t die&lt;/A&gt;&quot; triggered my hidden thoughts about IDS.&lt;/P&gt;
&lt;P&gt;Rather than thinking about IDS as a piece of device/software that provides fancy features. Let me try to summarize some assertions about&amp;nbsp;IDS:&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;
&lt;P&gt;IDS can capture&amp;nbsp;tons of intrusion&amp;nbsp;events, there is so much of don&#39;t care events it is difficult&amp;nbsp;to single out event such as zero day event in the midst of such noise. &lt;/P&gt;
&lt;P&gt;It requires tremendous effort to sift through the log and derive meaningful actions out of the log entries.&lt;/P&gt;
&lt;P&gt;IDS needs a dedicated&amp;nbsp;administrator to manage.&amp;nbsp;An administrator&amp;nbsp;who won&#39;t get bored of looking at all the packets and patterns, a truly boring job for a security engineer. Probably this job would interest a geekier person and&amp;nbsp;geeks tend to their own interesting research!&lt;/P&gt;
&lt;P&gt;There are companies that do without IDS, and they do just fine. I agree with Alan&#39;s assessment that IDS is like&amp;nbsp;a Checkbox in most cases.&amp;nbsp; Business can run without IDS just fine, why invest in such a technology?&lt;/P&gt;
&lt;P&gt;Firewalls and other devices have built in features of IDS, so why invest in a separate product.&lt;/P&gt;
&lt;P&gt;IDS is like Vitamins, nice to have, not having won&#39;t kill you in most cases. Customers are willing to pay for Pain Killers because they have to address their pain right away. For Vitamins, they can wait. Stop and think for moment, without Anti-virus&amp;nbsp;product,&amp;nbsp;businesses can&#39;t run for few days. But, without IDS, most&amp;nbsp;businesses can run just fine and I base it out of my own experience.&lt;/P&gt;
&lt;P&gt;Probably, I would have offended folks from the IDS camp. I have a good friend who is a founder of an IDS&amp;nbsp;company, I am sure he will react differently if he reads my narratives about IDS.&amp;nbsp;&amp;nbsp;Once businesses start realizing that&amp;nbsp;IDS is&amp;nbsp;a Checkbox, they will scale down their investments in this area. In the current economic climate, financial institutions are not doing well. Financial&amp;nbsp;institutions are big&amp;nbsp;customers in terms of security products, with the current scenario of financial meltdown, they would scale down heavily on their spending on Vitamins. &lt;/P&gt;
&lt;P&gt;Running IDS software on VMware sounds fancy.&amp;nbsp;&amp;nbsp;Technology does not matter unless you can address real world pain and prove the&amp;nbsp;utilitarian value of such a technology. I am really surprised that&amp;nbsp;IDS continues to exist. Proof&amp;nbsp;of existence does not forebode&amp;nbsp;great future. Running IDS on VMware does not make it any more utilitarian.&amp;nbsp;I see a bleak future for IDS.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Cute names can&#39;t come to rescue</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2008/8/23/3852899.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2008/8/23/3852899.html</guid>
    <pubDate>Sat, 23 Aug 2008 23:26:05 -0700</pubDate>
    <description>&lt;P&gt;Most of us have heard the conversations about looming threat to survival&amp;nbsp;Fannie Mae and Freddie Mac. Their names are cute but it can&#39;t help fix&amp;nbsp;a bad strategy of making money by dishing out bad loans.&lt;/P&gt;
&lt;P&gt;I have had interaction with several security project&amp;nbsp;managers who were very good in creating a buzz around their projects. Projects were given fancy names. The&amp;nbsp;funniest project name&amp;nbsp;I have heard was &quot;Baby Rhino&quot;. One day I get an email in my inbox with a subject line which says: Baby Rhino Caputred! - The email&amp;nbsp;got my attention, but the project did not gain any extra respect (because of the name) hardly there was any significant accomplishment in terms of its deliverable.&lt;/P&gt;
&lt;P&gt;I would rather stick with project&amp;nbsp;names that signify scope, relevance, meaning and value of&amp;nbsp; a project. It is not bad to market a project, but trying to market a project without delivering value is a gimmick. &lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Taming of the Information Security</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2008/7/9/3785025.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2008/7/9/3785025.html</guid>
    <pubDate>Wed, 09 Jul 2008 06:33:15 -0700</pubDate>
    <description>&lt;P&gt;&lt;FONT size=1&gt;In many mid-size to large organizations, information security grows up to become an unmanageable complex beast.&amp;nbsp; In some cases, this happens consciously where information security goes out of control, but in other cases this happens unconsciously where there is a slow but incremental increase in the complexity of information security which leads to chaos. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=1&gt;The information security field is not yet fully mature; there is a lack of cohesive interoperable framework.&amp;nbsp;&amp;nbsp; The rapidly evolving landscape adds to the existing problem. There are several examples: Intrusion Detection System (IDS) was quickly overtaken by Intrusion Prevention System (IPS).&amp;nbsp; On the Firewall arena: the focus has moved from perimeter security to end point security.&amp;nbsp; There are some security visionaries who are preaching inside-out security approach i.e. building products with information security in mind from the beginning of product development. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=1&gt;Threats are moving higher up in the OSI stack making it harder to detect. Hackers are becoming more sophisticated – there are powerful free open source hacking tools available at their disposal. Security managers driving security initiatives without coordination can result in pieces of puzzle that don&#39;t fit well. Agency problem i.e. security managers thinking more about their personal advancement rather than security of the company is bad for the company’s security initiative. Security leaders who do not have a clear vision of security at the component level, the administration level and the strategy level can only make information security even more convoluted. The CISO and acting CIO of US Dept of Veteran affairs resigned after the breach in May, 2006 where personal data of 26 million veterans and more than 2 million service members was stolen. This clearly demonstrates the accountability and visibility of security leadership.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=1&gt;&amp;nbsp;The attitude of IT security leaders and security team members has a significant impact on security.&amp;nbsp; Reckless buying of information security technology can result in wasteful expenditure and very little gain in efficiency. Not understanding the business perspective of security issues or security perspective of business issues can lead to poor security decisions. Using security as a mechanism to gain control rather than using it as a tool to reduce risk can only diminish the perceived value of security initiative. Implementing security as an afterthought rather than building it into the framework not only result in poor architectural decision. Security investment is more like buying insurance. Thinking security as a vehicle providing an ROI can result in wrong expectation and lead poor decision. The business in which a company operates contributes largely to the perceived importance to security. Financial institutions usually have a higher bar on security because of the very nature of their business and their exposure legal liability. It is a good idea for many technology companies to emulate financial institutions to raise their information security bar.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=1&gt;It could be a pipedream to accomplish complete&amp;nbsp; information security but accomplishing a well managed information security program is an attainable possibility.&lt;/FONT&gt;&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Security Function as a Business Enabler</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2008/6/27/3765919.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2008/6/27/3765919.html</guid>
    <pubDate>Fri, 27 Jun 2008 20:50:58 -0700</pubDate>
    <description>&lt;P&gt;In one of my earlier blog posts I branded Information Security function (as part of IT)&amp;nbsp;as an overhead of an overhead. It is utmost important for security manager to run the security function in a way that it enables the business. &lt;/P&gt;
&lt;P&gt;The various components (sub functions)&amp;nbsp;of security organization should align with the business objectives of the IT and the whole organization. There needs to be a cohesive security strategy in order to align the various comoponents. One good way of understanding the business objective is why is the business&amp;nbsp;parting with&amp;nbsp;money for deploying a specific security component. Why is business giving me money for Compliance? Why is business giving me money to implement IDP? Constitutive questions such as these will help you to understand the fundamental concerns for the business and based on these we can come up with a strategy suitably aligned with the business.&lt;/P&gt;
&lt;P&gt;One good example is the area of compliance.&amp;nbsp;Attempting to make&amp;nbsp;each every units of your business complaint with certain standards/legal regulations and so on would be a tall order. First define the scope, draw a circle around the units that need to be compliant, then come up with a strategy to make it compliant by formulating your objective - derived from the business objective of why the business&amp;nbsp;gave you&amp;nbsp;money.&lt;/P&gt;
&lt;P&gt;Any security implementation effort should have&amp;nbsp;a well defined focus (scope), business objective and strategy to bind the various components cohesively that aligns with the ultimate business objective. By this business will view security organization with dignity else security organization will end up being a spoke in the wheel of business.&lt;/P&gt;
&lt;P&gt;In the past, I was involved in discussion about the ROI of information security and security is insurance and so on. After eating the forbidden&amp;nbsp;apple from the tree of paradise, I realize security has neither ROI nor akin to insurance. Information security is way of doing business with due care. Security is way of enhancing the trust of a business among customers and thus enhancing the identity (or brand image of the company). Few years down the line people won&#39;t even question why you do security, it&amp;nbsp;will become a part&amp;nbsp;of&amp;nbsp; your background conversation. Nobody questions why we buy hybrid&amp;nbsp;vehicles&amp;nbsp;anymore right?&lt;/P&gt;
&lt;P&gt;If&amp;nbsp;components of security function&amp;nbsp;is not cohesively aligned with&amp;nbsp;business objective&amp;nbsp;it is spoke in the wheel of business else it is a brand enhancer of business.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG style=&quot;WIDTH: 370px; HEIGHT: 717px&quot; height=975 src=&quot;http://ravichar.blogharbor.com/Strategy.jpg&quot; width=545&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>The Order of Diminishing Returns</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2008/6/17/3750175.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2008/6/17/3750175.html</guid>
    <pubDate>Tue, 17 Jun 2008 21:41:37 -0700</pubDate>
    <description>&lt;P&gt;This is a classic management term which does not need any introduction to many folks. The more money you pour into the security budget the more money will be spent in buying unneeded security products which can increase the complexity and reduce efficiency of your security operations. The start-up companies that I worked long ago had installed&amp;nbsp;5 layers of Firewall to prevent intruders. The security manager claimed to me that it is there to &lt;STRONG&gt;really&lt;/STRONG&gt; protect the information assets, but sooner I realized these firewalls were not configured right and they were a set of&amp;nbsp; a fireholes than a set of&amp;nbsp;firewalls. Moreover, the maintenance costs in this type of&amp;nbsp; complex security framework can be humongous. Imagine poor me debugging the firewall rules across these 5 layers of firewalls. But, one thing for sure the job security of security professional who implemented these complex security framework is guaranteed.&amp;nbsp; In reality,the guy who implemented these 5 layers of firewall worked as a consultant for this start-up in the off hours and weekend!&lt;/P&gt;
&lt;P&gt;In reality I have seen well run security organizations, they are lean and mean. They not only provide continuous security thought leadership for the entire organization but also implement security in a simple and efficient way. The graph below gives a visual picture of what I mean by order of diminishing returns.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG style=&quot;WIDTH: 409px; HEIGHT: 282px&quot; height=336 src=&quot;http://ravichar.blogharbor.com/Order-of-diminishing.jpg&quot; width=409&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On a related note I have identified four different states of security organizations considering competence of employees and budget availability. Of course there are in-between states. I have considered only the extremes:&lt;/P&gt;
&lt;P&gt;&lt;IMG src=&quot;http://ravichar.blogharbor.com/Budget-vs-Competence.jpg&quot;&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://images.google.com/imgres?imgurl=http://www.cxoadvisory.com/blog/external/blog11-21-06/diminishing-returns.gif&amp;amp;imgrefurl=http://www.cxoadvisory.com/blog/external/blog11-21-06/&amp;amp;h=333&amp;amp;w=550&amp;amp;sz=8&amp;amp;hl=en&amp;amp;start=1&amp;amp;tbnid=hW3G0sAt7bJvIM:&amp;amp;tbnh=81&amp;amp;tbnw=133&amp;amp;prev=/images%3Fq%3Dorder%2Bof%2Bdiminishing%2Breturns%26gbv%3D2%26hl%3Den&quot;&gt;&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Application Due Care</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2008/2/18/3530987.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2008/2/18/3530987.html</guid>
    <pubDate>Mon, 18 Feb 2008 08:55:12 -0800</pubDate>
    <description>&lt;P&gt;Often I hear phrases such as &quot;if the application is truly built secure inside-out, then there is no need for other security layers&quot;.&amp;nbsp;Truly secure application is a far fetched statement.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. What is the application made of? - Complexity.&lt;/P&gt;
&lt;P&gt;2. How was the application built? - Methodology.&lt;/P&gt;
&lt;P&gt;3. Where does the application run? - Environment.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;#1. Complexity&lt;/STRONG&gt; -&amp;nbsp;Applications&amp;nbsp;are developed using one or more of open source software, third party libraries, re-used libraries (from the past), middleware, database and the run-time environment. In order to develop a truly&amp;nbsp;secure application we need to ensure security in all of these components that go into building the application.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;#2. Methodology&lt;/STRONG&gt; -&amp;nbsp;The development methodology that&amp;nbsp;is employed to build the application. This brings up several issues:&amp;nbsp;customization work, secure&amp;nbsp;coding practice, outsourced development, offshore development,&amp;nbsp;peer review, development tools, security requirements as a&amp;nbsp;part of the design, source code scanning, threat modelling&amp;nbsp;and penetration testing.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;#3. Environment&lt;/STRONG&gt; -&amp;nbsp;Application&amp;nbsp;exist in an environment.&amp;nbsp;This brings up several considerations such as operating system,&amp;nbsp;virual operating system(such as VMware), other applications that&amp;nbsp;co-exist with this application,&amp;nbsp;CPU hardware, storage, network and&amp;nbsp;lastly whether the application runs behind the firewall or&amp;nbsp;in the DMZ.&lt;/P&gt;
&lt;P&gt;It is overstatement to say&amp;nbsp;that the application built using&amp;nbsp;secure development methodology is secure. All the three factors Complexity, Methodology and Environment should be considered to make a judgement call about application security. The pragmatic approach is to build application that is secure enough that poses risks that&amp;nbsp;are acceptable to business (customer) this is what I would like to call &quot;Application Due Care&quot;. &lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Security is Invisible and Customers won&#39;t Pay for Security</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2008/1/25/3486968.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2008/1/25/3486968.html</guid>
    <pubDate>Fri, 25 Jan 2008 19:06:11 -0800</pubDate>
    <description>&lt;P&gt;A few years ago a dentist that I consulted with recommended me Dental Protector for &lt;A href=&quot;http://hocks.com/Merchant2/merchant.mvc?Screen=PROD&amp;amp;Product_Code=4897898&amp;amp;gdftrk=viHSLsl6E37tLP/85HJLprLdLyHsfGZ4PWMsWY2Mnr/4JYPVkETwIXwjocOi3cdIzkmvlRKFfQp8bN6BBbVDQu8YUMsoFr5imzxfsoA965YKc0kLuWWPT~o1FsiusA3KSN3uNV84eijAkAc0o3wXIR8O0W2k3ZgaPEQoe5u1OBXe6V5CqW74XDT1sAkTrnIZVUa0A2pLzvVuhLQLWmy4F8PAw8xBLhOPdyEmqsa18gs_&quot;&gt;Night Time Teeth Grinding&lt;/A&gt;. She mentioned that I grind my teeth during sleep. How in this world can I disprove her statement unless I have some external observer to monitor me all night to validate my teeth grinding! &lt;/P&gt;
&lt;P&gt;Security is invisible. Customers are willing to pay for visible software product&amp;nbsp;functionality but not for secure software product&amp;nbsp;development methodology. Unfortunately, most of the security is in the backend, if security works well, truly,&amp;nbsp;it should be &quot;invisible&quot; and the fact that it hidden does not motivate customers to pay anything extra. Security incidents motivate customers to act, this is the time when security becomes visible but the limelight fades away as soon as this&amp;nbsp; incident is handled. &lt;/P&gt;
&lt;P&gt;We as security professionals&amp;nbsp;see:&amp;nbsp;the internal mechanics&amp;nbsp;of software security and also can speculate ramification of poor software security&amp;nbsp;in customer deployment. Because we&amp;nbsp;see this we can&#39;t expect customers to pay for it. Making security visible&amp;nbsp;to the customer will defeat the whole purpose of security and making it invisible diminishes the value of security. It is a dichotomy that we (as security professionals)&amp;nbsp;have to manage and live with.&amp;nbsp; Customers who notice and are aware of security may start check on&amp;nbsp;of the&amp;nbsp;security aspect of a product&amp;nbsp;before&amp;nbsp;buying it.&amp;nbsp;Unfortunately, security is just one aspect,&amp;nbsp;buying a specific product vs.&amp;nbsp;other products purely based on security is a pipe&amp;nbsp;dream.&amp;nbsp;In the distant future when all products have security built in,&amp;nbsp;security won&#39;t be a differentiator anymore and visibility of security will diminish even further.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If security was highly visible, we would find Steve Jobs touting security on stage at MacWorld. May be this is the reality check for security professionals.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Media and Our Mind - Risk is All About Perception</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2008/1/23/3482332.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2008/1/23/3482332.html</guid>
    <pubDate>Wed, 23 Jan 2008 07:22:32 -0800</pubDate>
    <description>&lt;P&gt;Dave has an excellent blog post on how media affects our risk perception. &lt;A href=&quot;http://blogs.netapp.com/dave/me_myself_and_i/index.html&quot;&gt;Dave Hitz&lt;/A&gt; is the founder of &lt;A href=&quot;www.netapp.com&quot;&gt;NetApp&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;This is the what Dave says:&lt;/P&gt;
&lt;P&gt;&quot;A good risk management plan &lt;EM&gt;should&lt;/EM&gt; take into account hurricanes, lost tapes, lost laptops, and maybe even terrorist attacks, but realistically, headlines typically don&#39;t highlight the most important risks. You are much more likely to lose data from human error or inadequately tested backup and recovery processes than from floods or attacks, but inadequate processes don&#39;t make good headlines. In addition, headlines fade quickly – if something becomes frequent it&#39;s often less newsworthy, but the risk remains. Our more sophisticated customers, like financial institutions, build risk management models that already include the items most likely to show up in the headlines, and if they use media reports at all, it&#39;s to update some aspect of their model, like the probability of a particular event, or the impact and cost. &lt;/P&gt;
&lt;P&gt;In summary, don&#39;t worry about terrorists until restore from your nightly backup is well tested. &quot;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;More details can be found on his blog&amp;nbsp;&lt;A href=&quot;http://blogs.netapp.com/dave/2007/06/shark_island_a_.html&quot;&gt;here.&lt;/A&gt;&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>An interesting Whitepaper on Web 2.0 Security &amp; Fortify Event</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2008/1/18/3473232.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2008/1/18/3473232.html</guid>
    <pubDate>Fri, 18 Jan 2008 07:40:36 -0800</pubDate>
    <description>&lt;P&gt;I was fortunate to be introduced to a good ex-Microsoft Security person, &lt;A href=&quot;http://www.truststix.com/about.html&quot;&gt;Shivaram Mysore&lt;/A&gt;.&amp;nbsp; He has an interesting whitepaper on &lt;A href=&quot;http://www.truststix.com/resources/whitepapers/web20security/Web2_0Security.pdf&quot;&gt;Web 2.0 Security&lt;/A&gt;. It is worthy read.&amp;nbsp;The whitepaper&amp;nbsp;gives a brief introduction to service models available and aligns your thought process around securing Web 2.0 around these service architectures.&lt;/P&gt;
&lt;P&gt;I recently attended the pre-screening of the Information Security documentary titled: &lt;A href=&quot;http://www.youtube.com/watch?v=-5zxOLZ5jXM&quot;&gt;The New Face of Cybercrime&lt;/A&gt;. The documentary was very nicely done, considering the Director Fredric Golding has no background in Information Security. &lt;/P&gt;
&lt;P&gt;The thought leaders panel discussion was very stimulating. Being an analogy person, I liked analogy&amp;nbsp;narrated by&amp;nbsp;&lt;A href=&quot;http://www.aeispeakers.com/speakerbio.php?SpeakerID=1192&quot;&gt;Howard Schmidt&lt;/A&gt; , Former White House Security Advisor, about evolution of Information Security and evolution of Firefighting. In the past,&amp;nbsp;Firefighting was&amp;nbsp;a&amp;nbsp;reactive approach but these days&amp;nbsp;people factor in the the threat of fire pro-actively into the building design - sprinklers, fire retardant materials and so on. Another panelist &lt;A href=&quot;http://www.kpcb.com/team/schlein&quot;&gt;Ted Schlein&lt;/A&gt;, Managing Partner&amp;nbsp;KPCB, mentioned the security spending&amp;nbsp;is&amp;nbsp;around&amp;nbsp;$12 billion/year vs. the loss due to information security breach&amp;nbsp;is&amp;nbsp;around $100 billion/year -&amp;nbsp;trail of money always sounds interesting to me.&amp;nbsp;There&amp;nbsp;were lots of discussions about Inside-Out vs. Outside-In approach to Information Security. &lt;/P&gt;
&lt;P&gt;Thanks to &lt;A href=&quot;https://www.blogware.com/www.fortifysoftware.com&quot;&gt;Fortify &lt;/A&gt;for putting this event together. I am sure we need more such events should happen amongst the executive crowd to bring a high level of security awareness.&lt;/P&gt;
&lt;P&gt;Lastly,&amp;nbsp;I would like conclude this post by quoting the importance of user awareness because user awareness determines the&amp;nbsp;&quot;usage&quot; which&amp;nbsp;is a very important component&amp;nbsp;for a&amp;nbsp;the threat model of an information system. I conclude by repeating the popular quote:&amp;nbsp;&quot;There is no patch for stupidity&quot;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Excellent addition to Information Security Blogging Community</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2007/11/21/3368913.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2007/11/21/3368913.html</guid>
    <pubDate>Wed, 21 Nov 2007 18:43:11 -0800</pubDate>
    <description>&lt;P&gt;My good friend, Muni Tripathi has started blogging on Information Security. You can read his blog about security at:&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://muni-on-security.blogspot.com/&quot;&gt;http://muni-on-security.blogspot.com/&lt;/A&gt;&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Getting vulnerabilities in the application fixed</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2007/10/27/3317198.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2007/10/27/3317198.html</guid>
    <pubDate>Sat, 27 Oct 2007 13:20:07 -0700</pubDate>
    <description>&lt;P&gt;I have been approached by few security professionals about the problem they encounter in getting software developers to fix the vulnerabilities that is detected in the application.&lt;/P&gt;
&lt;P&gt;Let us accept the fact that developers are&amp;nbsp;mostly busy focusing their time and effort on the functionality of application. Most of the time the software development manager gets away by using the busy excuse. One approach that I suggest you could&amp;nbsp; is to rank the vulnerabilities based on &quot;severity&quot; (how bad if the vulnerability is exploited)&amp;nbsp;and &quot;threat&quot; (how likely the vulnerability exploit is)&amp;nbsp;and&amp;nbsp;communicate this list&amp;nbsp;to the software development team. Give the software development manager time to fix the vulnerabilities - usually the time that the software development manager thinks that is acceptable.&lt;/P&gt;
&lt;P&gt;If the vulnerabilities are not acted up on despite of your first meeting, then try this route:&amp;nbsp;require the software development manager and the business owner of the application to sign a business&amp;nbsp;risk acceptance form. The risk acceptance form could be as simple as a word document with a list of high severity/threat vulnerabilities and a narrative that&amp;nbsp;states that signatories of the form acknowledge the existence of vulnerabilities (that you communicated)&amp;nbsp;and have accepted the&amp;nbsp;risk&amp;nbsp;(posed by the&amp;nbsp;vulnerabilities) for&amp;nbsp;a time period specified in the form. This way as a security professional you are covered that you did your job in communicating the security risk to the stakeholders. Now that they have signed on the form if something bad&amp;nbsp; event happens the accountability of the event is outside of you.&lt;/P&gt;
&lt;P&gt;You may find out that, business risk acceptance form is a good tool to motivate software development&amp;nbsp;manager - would&amp;nbsp;mobilize resources to act on vulnerabilities rather than&amp;nbsp;sign the business risk acceptance form&amp;nbsp;.&amp;nbsp;&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Web 2.0 SecureD. DelivereD.  :)</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2007/10/13/3288697.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2007/10/13/3288697.html</guid>
    <pubDate>Sat, 13 Oct 2007 09:29:44 -0700</pubDate>
    <description>&lt;P&gt;Web 2.0 has become a well accepted jargon in the current marketplace. It is a set of new web based technologies that enable building of on-line communities.&lt;/P&gt;
&lt;P&gt;Web 2.0 is a democracy of user communities [thanks to Paul Graham for his definition].&amp;nbsp;Web 2.0&amp;nbsp;gives more power&amp;nbsp;for the&amp;nbsp;users to interact, customize, share and leverage. &lt;/P&gt;
&lt;P&gt;The democratization of users bring significant problems.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;1. Loss of privacy:&lt;/STRONG&gt; Ease of use motivates users to upload personal information. Many users are not aware of ramifications of loss of personal information or they don&#39;t even think on those lines. A good example is an employer going through the Facebook entry of a potential hire.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;2. Hackers Paradise:&lt;/STRONG&gt; New technology brings new vulnerabilities. Hackers are having a party exploiting Web 2.0 based applications. We are more vulnerable&amp;nbsp;with Web 2.0&amp;nbsp;currently&amp;nbsp;than with Web 1.0.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;3. Lots of Junk:&lt;/STRONG&gt; Take for example Wikipedia, anyone/anywhere can edit the content [everybody is an expert!]. How can I trust the quality of information?&amp;nbsp;It is not possible to reference Wikipedia in&amp;nbsp;a research paper.&amp;nbsp;Moreover, it puts burden on the users to sift good and bad stuff. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;4. Copyright/Intellectual Property Violations:&lt;/STRONG&gt; I don&#39;t have to say much about this. Web 2.0 provides a platform for such violations and magnifies the impact [Record label sues Napster, Viacom sues Google over YouTube clips].&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;5. Other Social Problems:&lt;/STRONG&gt; People can interact on-line in ways that was not possible before. These new interactions create new set of social problems. &lt;/P&gt;
&lt;P&gt;and many more problems that can make my blog post long and boring..&lt;/P&gt;
&lt;P&gt;Some of the above aspects can be addressed: for example building web&amp;nbsp;applications securely&amp;nbsp;ground up&amp;nbsp;can help prevent hackers. Designing Web 2.0 application&amp;nbsp;to&amp;nbsp;ensure users&amp;nbsp;use the platform responsibly is a good idea too. Spreading security awareness education to on-line communities&amp;nbsp;can help engender responsible/secure use of the web.&lt;/P&gt;
&lt;P&gt;Security should be a feature added to Web 2.0 and let&#39;s call Web 2.T3. The&amp;nbsp;&quot;T3&quot; represents the security triad - Confidentiality, Integrity and Availability.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Though security does not address all aspects of Web 2.0. Web 2.T3 surely will be &amp;nbsp;a better place to live.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>The Moo Security through Sacredness</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2007/8/29/3191987.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2007/8/29/3191987.html</guid>
    <pubDate>Wed, 29 Aug 2007 04:30:13 -0700</pubDate>
    <description>&lt;P&gt;&lt;IMG src=&quot;http://ravichar.blogharbor.com/moo1.JPG&quot;&gt;&lt;/P&gt;
&lt;P&gt;I am currently in India, attending my dad&#39;s health concern. I stay awake at wee hours, still recovering from the jetlag. Cow&amp;nbsp;is&amp;nbsp;considered a sacred animal&amp;nbsp;in India for multitude of reasons:&lt;/P&gt;
&lt;P&gt;1. Cow gives milk which is a main source of protien in many parts of India. &lt;/P&gt;
&lt;P&gt;2. Diluted cow&#39;s milk is given&amp;nbsp; to newly born baby in cases where mom is not lactating hence elevating the status of a cow to that of a mom.&lt;/P&gt;
&lt;P&gt;3. Cow&#39;s dung can be used as manure and also dried dung cake&amp;nbsp;is used&amp;nbsp; as fuel.&lt;/P&gt;
&lt;P&gt;4. Cow&#39;s urine is used as a cleansing agent and also for other medicinal purpose.&lt;/P&gt;
&lt;P&gt;Cow is considered sacred because of its utility value to common people. Cow roams around in the streets of my hometown freely and they are unharmed because they are sacred.&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;By&amp;nbsp;being sacred, cow is the most &lt;STRONG&gt;secure &lt;/STRONG&gt;animal over here.&lt;/P&gt;
&lt;P&gt;Security&amp;nbsp;function is considered as an extension of IT, it is an overhead of an overhead&amp;nbsp;-&amp;nbsp;it&amp;nbsp;is not sacred. Security function usually is the foremost to feel the pinch due to IT budget cut. A good way to make security function&amp;nbsp;&quot;secure&quot; is to make it sacred. There are standards like ISO27001, COBIT which are well respected and considered sacred in the security domain. By conformance of security&amp;nbsp;function to such standards we can not only create a perception of &quot;sacredness&quot; for the security program but also communicate value of the program easily through the standard&#39;s framework.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
  <item>
    <dc:creator>RaviC</dc:creator>
    <title>Lost laptop = Lost data!</title>
    <link>http://ravichar.blogharbor.com/blog/_archives/2007/8/18/3166459.html</link>
    <guid>http://ravichar.blogharbor.com/blog/_archives/2007/8/18/3166459.html</guid>
    <pubDate>Sat, 18 Aug 2007 08:28:15 -0700</pubDate>
    <description>&lt;P&gt;&lt;FONT face=&quot;Times New Roman,Times,serif&quot;&gt;Laptop has become our essential travel companion.&amp;nbsp;Lost&amp;nbsp;brand new laptop without personal or company data will&amp;nbsp;result in a loss of current&amp;nbsp;market value of the laptop. Lost laptop with personal or company data can result in a loss which can depend on the value of the &quot;data&quot;. It is easier to make amends for the lost laptop but making amends for lost valuable company data or valuable personal data may not be possible.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=&quot;Times New Roman,Times,serif&quot;&gt;It is very important for us to be &quot;laptop data aware&quot; i.e.&amp;nbsp;the categories of&amp;nbsp;data it has and&amp;nbsp;the consequences of lost data.&amp;nbsp;A good practice is to treat your &lt;STRONG&gt;laptop like your wallet&lt;/STRONG&gt;. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=&quot;Times New Roman,Times,serif&quot;&gt;I found these 9 tips on &lt;/FONT&gt;&lt;A href=&quot;http://www.microsoft.com/atwork/stayconnected/laptopsecurity.mspx&quot;&gt;&lt;FONT face=&quot;Times New Roman,Times,serif&quot;&gt;Microsoft website&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=&quot;Times New Roman,Times,serif&quot;&gt;. These tips are really thoughtful and well written and hence I like to repeat it below:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=&quot;Times New Roman,Times,serif&quot;&gt;Use these 9 tips to learn how you can keep your laptop more secure when you&#39;re on the road.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;
&lt;TABLE class=numberedList cellSpacing=0 cellPadding=0 border=0&gt;
&lt;TBODY&gt;
&lt;TR vAlign=top&gt;
&lt;TD class=listNumber noWrap align=right&gt;
&lt;P&gt;1.&lt;/P&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;Avoid using computer bags. Computer bags can make it obvious that you&#39;re carrying a laptop. Instead, try toting your laptop in something more common like a padded briefcase or suitcase.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR vAlign=top&gt;
&lt;TD class=listNumber noWrap align=right&gt;
&lt;P&gt;2.&lt;/P&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;Never leave access numbers or passwords in your carrying case. Keeping your password with your laptop is like keeping the keys in the car. Without your password or important access numbers it will be more difficult for a thief to access your personal and corporate information.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR vAlign=top&gt;
&lt;TD class=listNumber noWrap align=right&gt;
&lt;P&gt;3.&lt;/P&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;Carry your laptop with you. Always take your laptop on the plane or train rather then checking it with your luggage. It&#39;s easy to lose luggage and it&#39;s just as easy to lose your laptop. If you&#39;re traveling by car, keep your laptop out of sight. For example, lock it in the trunk when you&#39;re not using it.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR vAlign=top&gt;
&lt;TD class=listNumber noWrap align=right&gt;
&lt;P&gt;4.&lt;/P&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;Encrypt your data. If someone should get your laptop and gain access to your files, encryption can give you another layer of protection. With Windows XP and Windows Vista you can choose to encrypt files and folders. Then, even if someone gains access to an important file, they can&#39;t decrypt it and see your information. Learn more about how to &lt;A href=&quot;http://www.microsoft.com/windowsxp/using/security/learnmore/encryptdata.mspx&quot;&gt;encrypt your data with Windows XP&lt;/A&gt; or &lt;A href=&quot;http://windowshelp.microsoft.com/Windows/en-US/Help/5a2b6b98-9833-4d73-967e-9293bd1a54e91033.mspx&quot;&gt;encrypt your data with Windows Vista&lt;/A&gt;.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR vAlign=top&gt;
&lt;TD class=listNumber noWrap align=right&gt;
&lt;P&gt;5.&lt;/P&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;Keep your eye on your laptop. When you go through airport security don&#39;t lose sight of your bag. Hold your bag until the person in front of you has gone through the metal detector. Many bags look alike and yours can easily be lost in the shuffle.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR vAlign=top&gt;
&lt;TD class=listNumber noWrap align=right&gt;
&lt;P&gt;6.&lt;/P&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;Avoid setting your laptop on the floor. Putting your laptop on the floor is an easy way to forget or lose track of it. If you have to set it down, try to place it between your feet or against your leg (so you&#39;re always aware it&#39;s there).&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR vAlign=top&gt;
&lt;TD class=listNumber noWrap align=right&gt;
&lt;P&gt;7.&lt;/P&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;Buy a laptop security device. If you need to leave your laptop in a room or at your desk, use a laptop security cable to securely attach it to a heavy chair, table, or desk. The cable makes it more difficult for someone to take your laptop. There are also programs that will report the location of a stolen laptop. They work when the laptop connects to the Internet, and can report the laptop&#39;s exact physical location. Some tracing programs include &lt;A href=&quot;http://www.sentryinc.com/&quot;&gt;CyberAngel&lt;/A&gt; and &lt;A href=&quot;http://www.computrace.com/&quot;&gt;ComputracePlus&lt;/A&gt;.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR vAlign=top&gt;
&lt;TD class=listNumber noWrap align=right&gt;
&lt;P&gt;8.&lt;/P&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;Use a screen guard. These guards help prevent people from peeking over your shoulder as you work on sensitive information in a public place. This is especially helpful when you&#39;re traveling or need to work in a crowded area. This screen guard from &lt;A href=&quot;http://www.secure-it.com/products/privacy_notebook.htm&quot;&gt;Secure-It&lt;/A&gt; is just one example of a screen guard you could use.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR vAlign=top&gt;
&lt;TD class=listNumber noWrap align=right&gt;
&lt;P&gt;9.&lt;/P&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;Try not to leave your laptop in your hotel room or with the front desk. Too many things have been lost in hotel rooms and may not be completely secure. If you must leave your laptop in your room, put the &quot;do not disturb&quot; sign on the door.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;</description>
    
    <category domain="http://ravichar.blogharbor.com/blog">Main Page</category>
    
    
    
    
  </item>
  
</channel>
</rss>
